CISA sent an unusual warning late last week. The federal cybersecurity agency instructed government IT departments to drop everything and patch their Windows servers.
The source of all their fears? The Zerologon vulnerability, disclosed last week. Augusts patch Tuesday fixed the bug, but its feared many organizations will have delayed installing it on their AD domain controllers.
The thing is,Zerologon rates a perfect 10 on the CVSS scale. In todays SBBlogwatch, we run and hide.
Your humble blogwatchercurated these bloggy bits for your entertainment. Not to mention:Maiden Goes To Hollywood.
Whats the craic, Zack?Mister Whittaker reportsHomeland Security issues rare emergency alert:
The Cybersecurity and Infrastructure Security Agency, better known as CISA, [is] requiring all federal departments and agencies to immediately patch any Windows servers vulnerable to the so-called Zerologon attackciting an unacceptable risk to government networks. Rated the maximum 10.0 in severity, [it] could allow an attacker to take control of any or all computers on a vulnerable network, including domain controllers.The bug was appropriately called Zerologon, because an attacker doesnt need to steal or use any network passwords to gain access to the domain controllers. With complete access to a network, an attacker could deploy malware, ransomware, or steal sensitive internal files.Although the CISA alert only applies to federal government networks, the agency said it strongly urges companies and consumers to patch their systems as soon as possible if not already.
AndDan Goodin addsAgencies that dont update must disconnect all domain controllers:
Microsoft published a patch last Tuesday. No later than 11:59pm EDT on Wednesday, agencies are to submit a completion report attesting the update has been applied to all affected servers or provide assurance that newly provisioned or previously disconnected servers will be patched.Its possible for attackers to exploit the vulnerability over the Internet [if] organizations expose their domain controllers. [Or, if they] have exposed Server Message Blockor Remote Procedure Call, [it] may be exploitable. Queries using the Binary Edge search service show that almost 30,000 domain controllers are viewable and another 1.3 million servers have RPC exposed.Zerologon is tracked as CVE-2020-1472. Further raising that stakes was the release by multiple researchers of proof-of-concept exploit code that could provide a roadmap for malicious hackers.Researchers continue to find evidence that people are actively developing attack code. Given the stakes and the amount of publicly available information about the vulnerability, it wouldnt be surprising to see in-the-wild exploits emerge in the coming days.
Feeling smug because you dont use Windows?Stop that, say Sambas Andrew Bartlett and Douglas Bagnall:
Installations running Samba asthe Active Directory DC [or] the classic/NT4-style DC [are] vulnerable. However, since version 4.8the default behaviour of Samba has been to insist on a secure netlogon channelequivalent to having server schannel = yes in the smb.conf.Versions 4.8 and above are not vulnerable unless they have the smb.conf lines server schannel = no or server schannel = auto. Samba versions 4.7 and below are vulnerable unless they have server schannel = yes. Each domain controller needs the correct settings in its smb.conf.Samba 4.10.18, 4.11.13, and 4.12.7 have been issued as security releases to correct the defect. Samba administrators are advised to upgrade to these releases or apply the patch as soon as possible.Our Code, Our Bugs, Our Responsibility.
Wait. Pause.?Why havent these IT people already done the job? v1 cant understand whats taking them so long:
The CVE was initially released on August 11. Funny theyre just now in a hurry to patch a severity-10 thats been out now for six weeks.Granted, it took Microsoft until last Tuesday to publish a patch, but any competent admin would have looked at that and said that goes on now and has already closed that barn door. Sure, tell the idiots to get it done immediately, then review the completion reports and fire everyone that waited until they were ordered to patch their servers, and hire competent replacements.
Butacdha reckons it aint that simple:
Youre missing the biggest reason: enterprise IT shops with strict change management processes and, especially in government, years of austerity budgets cutting resources for both sysadmins and rigorous testing.If you have a charge management process which takes a month to approve updates, the problem is not the sysadmin. If years of skimping means that the operators are afraid to patch because theyll be punished if it breaks things and they dont have a robust testing process, the problem is not the sysadmin.This is more expensive than people like to admit. You either need to accept lower security/reliability or spend more on staff, capacity, and licenses. Lots of places try to cut that corner and itll seem to work until, as Warren Buffet likes to say, the tide goes out.This is a really tricky problem in government because the pay scales can be very hard to change. Historically the higher-level positions were senior and relatively limited, so its not like you can just effortlessly bump all of your developer positions up to the highest grade without hitting budget caps. That probably means youre hiring people at lower levels which are more like entry level pay.
AndDeputy Cartmans been there done that bought the T-shirt:
Once organizations reach a certain size, they seem to instill a very very strong sense of Dont rock the boat if you dont have to mindset. You want to be proactive and apply a patch? Well what if it breaks something!? Just sit on your ***, keep looking at Tik-Tok, and counting down the days for your pension.Fix **** after the duct tape breaks, and move on with your life. Im already starting to feel this way at my defense company job due to its size. Fixing all the **** Im seeing thats pants-on-head stupid would go about as well as punching a concrete wall until my fists are hamburger.Just roll your eyes, take your time with that 8th cup of coffee, and just do what you can.
What went wrong, anyway?With a neat precis, heres tialaramex:
This is an amazing bug. What happens is, youre supposed to fill out a bunch of bytes as proof of who you are, and then a bunch of bytes that represent stuff like seconds since the start of the Unix epoch. If you cant do this, NetLogon figures you arent really who you say you are.The exploit is: Fill everything out with all zeroes. This will succeed one time in 256 on average.[It] isnt a bug in the code, its a design mistake: If you implement exactly what Microsofts design document says for NetLogon, one time in 256 all zeroes lets you in. By design. Stupid stupid design.It stands out how terrible Microsoft is at cryptographic design. Microsoft does this over and over.
IT people deserve blame too.Coppercloud dreams up the best simile:
Wait, people have domain controllers present on the public internet? Like, no firewall, port forwarded or no NAT, no VPN? Just out there?This is plugging a hole in a leaky chicken fence and hoping it floats.
Cue:the inevitable conspiracy theory. jiggawatts approaches 88 mph:
I am now convinced that Microsoft is purposefully degrading the quality of the cryptography at the behest of the NSA. Microsoft products have all of the following current cryptographic problems: There is no support for TLS 1.3. HSTS is very hit and miss. Until very recently, youd have to jump through hoops to enable TLS 1.1 and 1.2. Across a forest trust, RC4 is the default cipher. If you try to enforce AES ciphers youll break some forms of single-sign-on from Azure AD. If you use ECC certificates, youre stuck with the handful of now very thoroughly legacy curves. You cant have elliptic curve certificates with: NDES, AD FS, SQL Server, SCCM until very recently, and in fact just about every Microsoft product except for IIS. Which I remind you still cant do TLS 1.3. Azure Key Vault cant issue anything but RSA certificates from third-party CAs. The NSA does exist. They do degrade cryptographic algorithms, either through national security letters or simply bribery. The Dual_EC_DRBG fiasco happened. It really happened. Private United States based organisations do cooperate with these programs, either willingly or because they are forced to.Its one thing to accuse a neighbour randomly of murder. Its entirely another thing if you see them putting a shockingly large and heavy rolled up carpet in the boot of their car.
Meanwhile,kaur thinks a thought experiment:
Every country in the world is [asking] questions: Why do we use a consumer OS built by an US company? Can we trust USA to be our ally and not abuse its power over Microsoft? Can we trust USA to stay our ally in the forseeable future?
Maiden Goes To Hollywood
Previously in And Finally
You have been readingSBBlogwatchbyRichiJennings. Richi curates the best bloggy bits, finest forums, and weirdest websites so you dont have to. Hate mail may be directed Ask your doctor before reading. Your mileage may vary. E&OE. 30.
Image sauce: Ryan McGuire (via Pixabay)
Recent Articles By Author
See the original post:
Feds Yell PATCH NOW over Windows AD Zerologon Vuln - Security Boulevard
- How to buy the best carpet - Which? - March 9th, 2025 [March 9th, 2025]
- The Brand Behind Costco's Carpet (And If Installation Is Included) - MSN - November 12th, 2024 [November 12th, 2024]
- How to Install Carpet - The Home Depot - April 5th, 2023 [April 5th, 2023]
- Top 10 Best Carpet Installation in Indianapolis, IN | Angi - April 5th, 2023 [April 5th, 2023]
- NY Lawmaker Slams Gillibrand: 'There She Goes Again' - WIBX AM 950 - September 22nd, 2022 [September 22nd, 2022]
- Eco-Friendly Home Renovations That Give You Top ROI - House Digest - September 22nd, 2022 [September 22nd, 2022]
- A Dutch-Norwegian startup wants to open a whole new frontier of renewable energy with solar farms that float on the oceans surface - Fortune - September 22nd, 2022 [September 22nd, 2022]
- Saturday night fever - Winnipeg Free Press - September 22nd, 2022 [September 22nd, 2022]
- How Qatar Became an Arts and Architecture Hot Spot - Artful Living - September 22nd, 2022 [September 22nd, 2022]
- Art Attack: Everything to See in Denver Galleries This Week - Westword - September 22nd, 2022 [September 22nd, 2022]
- Reflecting on the tumbles of childhood - The Oxford Eagle - Oxford Eagle - August 20th, 2022 [August 20th, 2022]
- Suncoast passionate about flooring and professional installation - Navarre Press - August 20th, 2022 [August 20th, 2022]
- Visitors to the reopened home of Emily Dickinson may know the 19th century poet first via pop culture - Maine Public - August 20th, 2022 [August 20th, 2022]
- A Dehli home at DLF Chattarpur Farms where every element is a work of art - Architectural Digest India - August 20th, 2022 [August 20th, 2022]
- Michael Beltran: Sacking Andrew Warren was right, and constitutional. Here's why - Andrew Warren - Florida Politics - August 20th, 2022 [August 20th, 2022]
- City repairs and remodeling projects approved - Plant City Observer - August 20th, 2022 [August 20th, 2022]
- This Montreal Comedy Party Is Closing Out The Summer With Free Shots & A Hilarious Lineup - MTL Blog - August 20th, 2022 [August 20th, 2022]
- Hamilton Island Race Week rivalries reignited - Sydney Morning Herald - August 20th, 2022 [August 20th, 2022]
- Te Hkoi Toi: Finding the fine art in photography - Stuff - August 20th, 2022 [August 20th, 2022]
- Homeowner frustrated with door leaks - Daily Herald - January 25th, 2022 [January 25th, 2022]
- The 25 Best Museum Buildings of the Past 100 Years - ARTnews - January 25th, 2022 [January 25th, 2022]
- SPONSORED: Colony Factory Crafted Homes Hiring for Several Positions - - January 25th, 2022 [January 25th, 2022]
- Traffic cameras at school zones, salary increases for DA's Office and Board Elections discussed at BOC Regular Meeting - Americus Times-Recorder |... - January 25th, 2022 [January 25th, 2022]
- 5 Home decor ideas that can give a revamp to your small apartment - PINKVILLA - January 25th, 2022 [January 25th, 2022]
- Security: the pitfalls of being hacked and how to avoid them using basic IT skills KNXtoday - KNXtoday - January 25th, 2022 [January 25th, 2022]
- Idaho Leads the Nation When it Comes to Inflation - News Radio 1310 KLIX - January 25th, 2022 [January 25th, 2022]
- Carpet Land | Omaha | Lincoln | Sioux Falls | Free ... - November 4th, 2021 [November 4th, 2021]
- Carpet Installation & Maintenance - How To Guides & Videos - November 4th, 2021 [November 4th, 2021]
- Carpet trends 2021 the stylish new looks for fabulous ... - November 4th, 2021 [November 4th, 2021]
- How to choose a carpet and ensure it stands the test of time - Irish Examiner - November 4th, 2021 [November 4th, 2021]
- 34 Cheap And Random Products Reviewers Say Are Worth The Money - BuzzFeed - November 4th, 2021 [November 4th, 2021]
- Best Flooring Installation Companies Of 2021 Forbes Advisor - Forbes - November 4th, 2021 [November 4th, 2021]
- These Families are Stuck at Home During Covid, But Have Plenty of Places to Go - Mansion Global - February 20th, 2021 [February 20th, 2021]
- Emily Dickinson museum plans $2M project to restore period wallpaper, floor coverings and other decor - GazetteNET - February 20th, 2021 [February 20th, 2021]
- William Ceder Obituary - (1940 - 2021) - Central City, NE - The Grand Island Independent - - February 20th, 2021 [February 20th, 2021]
- How to stay safe and warm both with or without power - - February 20th, 2021 [February 20th, 2021]
- Red Cross: Winter storms and preventing, thawing frozen pipes - Shawnee News Star - February 20th, 2021 [February 20th, 2021]
- Ohio weather: How to stop your pipes from freezing and tips on staying warm during a cold snap - Akron Beacon Journal - February 20th, 2021 [February 20th, 2021]
- The Indian carpet makers weaving their magic globally - YourStory - February 9th, 2021 [February 9th, 2021]
- Netflix Partners With British Asian Artists INKQUISITIVE + CHILA KUMARI BURMAN To Create SUV Installations Inspired By THE WHITE TIGER - The Fan... - February 9th, 2021 [February 9th, 2021]
- Homeowner's Guide to Outdoor Carpet The Family Handyman - msnNOW - February 9th, 2021 [February 9th, 2021]
- Celebrities That Awkwardly Wore The Same Outfits On The Red Carpet - Nicki Swift - February 9th, 2021 [February 9th, 2021]
- Ohio Theatre to undergo renovation - Delaware Gazette - February 9th, 2021 [February 9th, 2021]
- Interface, Inc. To Broadcast Fourth Quarter and Fiscal Year 2020 Results Conference Call Over the Internet - McDuffie Progress - February 9th, 2021 [February 9th, 2021]
- National Burn Awareness Week raises awareness and prevents burn injuries February 7-13 is National Burn Awareness Week - Caswell Messenger - February 9th, 2021 [February 9th, 2021]
- These Hair Extension Care Tips Will Help Yours Last Longer - Allure - February 9th, 2021 [February 9th, 2021]
- Overfinch Levels-Up With A Limited-Edition Range Rover - Men's Book - February 9th, 2021 [February 9th, 2021]
- Norwood: A history of the Gospel Hall and Pine Street Centre - - February 9th, 2021 [February 9th, 2021]
- On creativity and the past: A curation of 6 artists | Daily Sabah - Daily Sabah - February 2nd, 2021 [February 2nd, 2021]
- SC&H Capital Advises Carpet & Wood Floor Liquidators on the Sale of Stock to an ESOP - Citybizlist - February 2nd, 2021 [February 2nd, 2021]
- CAPA puts capital budget allocation toward Ohio Theatre renovation - - February 2nd, 2021 [February 2nd, 2021]
- Chicopee City Council agrees to 2nd phase of City Hall renovations - - February 2nd, 2021 [February 2nd, 2021]
- It's Christmas in February at Clara's On the River - - February 2nd, 2021 [February 2nd, 2021]
- New year, new flooring with the help of Satolli Carpet and Floor Covering - - January 31st, 2021 [January 31st, 2021]
- New Paltz considers regulations for the use of gas-powered leaf blowers - Hudson Valley One - January 31st, 2021 [January 31st, 2021]
- How is a local organization working to honor Ripon tavern owner Bob Hilke? - Ripon Commonwealth Press - January 31st, 2021 [January 31st, 2021]
- Check Out 5 Times Oprah Winfrey Slayed The Red Carpet - HelloBeautiful - January 31st, 2021 [January 31st, 2021]
- 'Let there be light': Renovation of St. James Episcopal Church's illuminates once-dark sanctuary - The Advocate - January 31st, 2021 [January 31st, 2021]
- New 'Meet the Press' studio pays tribute to heart of democracy, free exchange of ideas - NewscastStudio - January 25th, 2021 [January 25th, 2021]
- Surprise bust of Csar Chvez in Joe Biden's office - Explica - January 22nd, 2021 [January 22nd, 2021]
- WeatherTech FloorLiners and Cargo Liners - Unboxing, installation, cleaning and review - BMWBLOG - January 22nd, 2021 [January 22nd, 2021]
- All the Inauguration Day Design Stories You Need to Know - Architectural Digest - January 22nd, 2021 [January 22nd, 2021]
- Watching Minari, I Saw My Immigrant Experience On The Screen For The First Time - WBEZ - January 3rd, 2021 [January 3rd, 2021]
- Lyric welcomes the new year with new stage - The Miami Times - January 3rd, 2021 [January 3rd, 2021]
- Two sides of the health care coin | Rocketminer | - Wyoming Tribune - January 3rd, 2021 [January 3rd, 2021]
- The River: Reflecting on New Year's days gone by on riverboats and saying a relieved goodbye to 2020 - User-generated content - January 3rd, 2021 [January 3rd, 2021]
- Grove City in 2021: Focus is on planning, not just for this year but for next 20-plus - ThisWeek Community News - January 3rd, 2021 [January 3rd, 2021]
- Crystals installed on Times Square New Year's ball - Yahoo News - January 3rd, 2021 [January 3rd, 2021]
- Blueprint in the works for $2.73 million renovation to Bangor sports complex - Bangor Daily News - January 3rd, 2021 [January 3rd, 2021]
- Year in review: 'Forever chemicals' contaminate Fairfield wells - Kennebec Journal and Morning Sentinel - January 3rd, 2021 [January 3rd, 2021]
- Top 10 Best The Gorilla Farm Car Mats 2020 Bestgamingpro - Best gaming pro - January 3rd, 2021 [January 3rd, 2021]
- Jan 03 On this day in Cambridgeshire history - In Your Area - January 3rd, 2021 [January 3rd, 2021]
- Where I Live: Woods of Shavano - San Antonio Report - January 3rd, 2021 [January 3rd, 2021]
- Permit Filed for Possible Moana Themed Elements Being Added to Lava Pool at Disney's Polynesian Village Resort - - December 25th, 2020 [December 25th, 2020]
- Here are the best art shows Boston missed in 2020 - The Boston Globe - December 25th, 2020 [December 25th, 2020]
- Totowa PAL Upgrades Sports Field With Installation Of Shaw Sports Turf - PR Web - December 25th, 2020 [December 25th, 2020]
- The Kaleidoscopic Art of Threatened Corals - Scientific American - December 25th, 2020 [December 25th, 2020]
- Carpet of flowers and tributes left to young man killed in Whitwick car crash - Leicestershire Live - December 25th, 2020 [December 25th, 2020]
- Big Homes Just Listed in the Park Hills Area - McDowell News - December 25th, 2020 [December 25th, 2020]